Aggregator
CVE-2026-9807 | GitLab Community Edition/Enterprise Edition up to 18.10.6/18.11.3/19.0.0 Access Token authorization (Nessus ID 317940 / WID-SEC-2026-1727)
CVE-2026-47104 | libusb up to 1.0.29 descriptor.c parse_iad_array out-of-bounds (ID 1813 / Nessus ID 317946)
CVE-2026-2601 | GitLab Enterprise Edition up to 18.10.6/18.11.3/19.0.0 authorization (EUVD-2026-32621 / Nessus ID 317947)
CVE-2026-9759 | Wireshark up to 4.4.15/4.6.5 ROHC Protocol Dissector null pointer dereference (EUVD-2026-32629 / Nessus ID 317943)
CVE-2026-47760 | TinyMCE up to 7.0.x cross site scripting (GHSA-mh5m-5hw4-5c69 / Nessus ID 317945)
CVE-2026-44465 | zed-industries zed up to 0.227.0 os command injection (GHSA-fj2r-rmw6-h222 / Nessus ID 317948)
CVE-2026-6713 | GitLab Community Edition/Enterprise Edition up to 18.10.6/18.11.3/19.0.0 Private Project authorization (EUVD-2026-32618 / Nessus ID 317949)
Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts
IBM security advisory (AV26-527)
Искали советские бомбы, а нашли далекие галактики. Как американские военные спутники случайно открыли гамма-всплески
瑞典政府呼吁家长在陪伴孩子时放下手机
Iranian Hackers Abuse AppDomainManager Hijacking to Evade EDR Detection
Iranian hackers have taken their cyberespionage playbook to a new level, deploying a sophisticated .NET hijacking technique to slip past endpoint defenses and target organizations across the United States, Israel, and the United Arab Emirates. The campaign intensified following a regional conflict that began on February 28, 2026, attributed to an Iran-linked advanced persistent threat […]
The post Iranian Hackers Abuse AppDomainManager Hijacking to Evade EDR Detection appeared first on Cyber Security News.
Microsoft security advisory – May 2026 monthly rollup (AV26-456) – Update 2
Critical Windows Netlogon RCE flaw now exploited in attacks
Critical Windows Netlogon RCE flaw now exploited in attacks
SideCopy Hackers Deploy Persistent XenoRAT Malware to Target Afghanistan Finance Ministry
A Pakistan-linked threat group known as SideCopy has launched a focused cyberattack against Afghanistan’s Ministry of Finance, deploying a persistent remote access tool called XenoRAT. The campaign, dubbed Operation XENOFISCAL, targeted provincial finance officials across all 34 Afghan Mustoufiats — regional revenue and finance directorates that form the fiscal backbone of the country. The attack […]
The post SideCopy Hackers Deploy Persistent XenoRAT Malware to Target Afghanistan Finance Ministry appeared first on Cyber Security News.